Files

693 B

Remaining Security Issues

  1. No rate limiting on /reauth — brute-force possible via export dialog
  2. No Content Security Policy (CSP) header — XSS could leak crypto key from sessionStorage
  3. Crypto key in sessionStorage (extractable) — necessary for refresh persistence, but XSS can steal it. HttpOnly cookie + service worker is more secure but complex
  4. No session rotation — same token until logout; if leaked, valid for 24h
  5. No 2FA — opted out of TOTP implementation
  6. Password generator modulo biasc.charAt(arr[i] % c.length) has slight bias when c.length does not divide 2^32; not practically exploitable